cancel
Showing results for 
Search instead for 
Did you mean: 

Provisioning of Portal Groups to Portal Roles in IdM

Matt_Marples
Participant
0 Kudos

Can anyone explain to me how portal groups to portal roles are provisioned to the relevant target systems through IdM?

Accepted Solutions (0)

Answers (3)

Answers (3)

Matt_Marples
Participant
0 Kudos

Many thanks for your advice, it has been really helpful.

former_member2987
Active Contributor
0 Kudos

Have you been able to set something up?

Thanks,

Matt

Matt_Marples
Participant
0 Kudos

Hi Matt,

Not had chance to set anything up, but someone now has explained to me how the Portal Roles are provisioned to our Portal when a Portal Group is assigned..

Thanks for this

Steffi_Warnecke
Active Contributor
0 Kudos

Hello Matthew,

to add to Matt's post it may be good to know, that portal groups (you talk about UME groups?) and portal roles will both be of the same type in IdM (called "privileges"). Maybe I didn't unterstand correctly, what you meant by

Provisioning of Portal Groups to Portal Roles

but you can't add a portal group to a portal role via IdM. Just users per se. You have to make that connection (adding the role to the group) in the portal itself and then can provision users to the portal group via IDM. Or directly to the portal role, if you want to.

But like I said, maybe that wasn't your question after all. Still I wanted to make sure, there is no missunderstanding.

Regards,

Steffi.

Matt_Marples
Participant
0 Kudos

Hi Steffi, yes we have UME groups and when the UME group is provisioned by applying for a business the relevant  portal roles are assigned. For example, we have UME groups that assign three portal roles at a time.

I just want to understand how IdM knows what portal roles belong to UME groups.

Many thanks.


Steffi_Warnecke
Active Contributor
0 Kudos

Hello Matthew,

the IDM won't know that, only the portal itself. You just add the users to the portal groups through IDM. But the connection between the UME group and its portal roles has to be made in the portal.

Regards,

Steffi.

former_member2987
Active Contributor
0 Kudos

Matthew,

To follow up on Steffi's post and to expand on my previous post, IDM reads the SAP Roles from the connected sys that you are working with  (ABAP or JAVA) and maps them into IDM as Privileges.  These privileges can be assigned directly or via the IDM Role concept. 

Therefore you can use IDM to create specific Roles comprised  of Privileges (think SAP Role Composites) and then assign them to users as needed.

Hope this helps.

Matt

former_member2987
Active Contributor
0 Kudos

Matthew,

Short form:

1. Run the initial load from the system that you want to gather roles from.

2. The roles will now be in IDM.  You can assign manually or through a task, or event.

Matt